FID Dual 1 GbE Compact Appliance
A palm-sized two-interface appliance for portable labs, field kits, and space-constrained inline deployments. Effective throughput depends on enabled FID functions, traffic characteristics, and configuration.
FID sits transparently between real endpoints so you can observe, filter, manipulate, and inject traffic without readdressing the endpoints.
FID is an extensible network experimentation platform for engineers who need to work with traffic in flight. It sits inline, learns the endpoints and conversations already present on the link, and maintains that context as traffic is observed, selectively diverted to a tool, or reinjected. That lets operator tooling participate in a live network without readdressing the endpoints or treating every packet as an isolated event. FID provides traffic-handling primitives, automation APIs, and extension points for standard and proprietary protocols while leaving protocol-specific test logic in operator tools and RIGS.
FID handles the traffic plumbing that makes inline tooling useful on a live network: it keeps the two directions of a selected conversation associated, lets unrelated replies continue inline, and uses learned network context when operator traffic returns to the wire. Protocol-specific test logic stays in packaged tools or reusable operator-developed RIGS.
FID handles the traffic paths. Your tools supply the protocol logic.
Illustrated IPv4 example: FID diverts one selected message from Endpoint A to a custom forwarding RIG, without sending an unchanged copy to B. The RIG’s illustrative protocol rule changes the payload from 20 to 25 and forwards it to Endpoint B. In this example, B echoes 25 in its reply. The reply pauses at the RIG, whose custom rule changes 25 back to 20 before forwarding it to A. Both directions use matching illustrative travel times and a pause at the tool, not measured processing latencies. Unselected messages cross FID unchanged. The RIG supplies protocol parsing, modification, forwarding and reverse handling; filtering alone does not forward the original message.
Observe live traffic and learn endpoint identity, direction, and conversation context before deciding what to intercept. Passive DNS and TLS Server Name Indication (SNI) observations add application-level clues without first diverting the traffic.
Select traffic by protocol and flow criteria while keeping the two directions of a conversation associated. Selected sessions can stay bound to an operator tool while unrelated return traffic continues to its intended endpoint.
Introduce operator-generated traffic into the live path using learned network context, then steer replies or tool-processed traffic back to the correct side without exposing the tool's private network identity on the target link.
Operator tools run in Docker containers attached to selected traffic. Inside the container, operators can use standard Linux networking interfaces, sockets, raw sockets, packet tools, and applications while FID handles the inline Layer 2 plumbing. The supported tool catalog includes shell access, mitmproxy, testssl.sh, and other packaged analysis utilities.
Capture selected traffic for offline analysis while retaining the live inline network context.
RIGS are operator-developed, reusable test modules and workflows built on FID's traffic access and automation interfaces.
Place FID between two network endpoints or network segments. Existing endpoint addressing remains unchanged.
Learn who is on each side of the link and how live conversations are flowing, while observing DNS activity and TLS SNI indications.
Select TCP or UDP conversations of interest and steer them to an operator tool while FID keeps their forward and return traffic associated.
Use a packaged Docker operator tool or an operator-developed RIG. RIGS can be built from customer-furnished protocol specifications, including Interface Control Documents (ICDs), observed traffic, operator knowledge, and user-defined test objectives.
Generate new test traffic or return tool-processed traffic to the live path using learned network context so it reaches the correct side and its replies return coherently.
Extension framework
FID provides the platform and APIs for traffic access. RIGS are reusable test modules or coordinated test workflows built on that platform by operators or integrators. They can use customer-furnished protocol specifications, including Interface Control Documents (ICDs), observed traffic, and operator knowledge, but FID does not automatically interpret those specifications or invent protocol semantics. Test logic and evaluation criteria remain user-defined.
Preserve or manipulate Ethernet identities and frame-level behavior.
Operate inline without requiring endpoint readdressing; control IP-level forwarding and translation.
Select and steer flows by transport context while maintaining stateful handling.
Attach protocol-aware tools and operator-developed RIGS for application and proprietary-message semantics.
A palm-sized two-interface appliance for portable labs, field kits, and space-constrained inline deployments. Effective throughput depends on enabled FID functions, traffic characteristics, and configuration.
A dedicated two-interface appliance for higher-rate inline analysis and experimentation. Effective throughput depends on enabled FID functions, traffic characteristics, and configuration. For customers with TAA requirements, Bowline can quote a hardware configuration whose TAA status and country of origin are documented with the quotation.
Pair FID with EtherShunt when you need remote insertion/removal plus hardware fail-safe bypass. EtherShunt-integrated operation is limited to 1 Gb.
FID works in path with the real endpoints, routes, MAC addresses, and IP addresses rather than reproducing the environment in an isolated lab.
Authorized inline testing can preserve endpoint-facing identities and the existing topology, allowing permitted workflows to be exercised in the same context seen by basic MAC/IP allowlists and other network controls.
Standard capabilities and packaged tools are available immediately, while operators or integrators can add proprietary protocol knowledge as reusable RIGS and automation.
24-month platform license
FID does not require cloud reach-back for normal operation and can run fully in connected, disconnected, or air-gapped environments. The 24-month platform license includes a quarterly offline maintenance checkpoint. When applicable updates are available, Bowline provides an offline maintenance package; when no update is needed, the checkpoint may consist of a status notice. Maintenance may include FID fixes plus applicable security, stability, and compatibility updates for the software baseline delivered and supported by Bowline after validation with FID. Confirmed defects may also be addressed with out-of-cycle fixes when appropriate.
During an active license term, customers can report FID defects to Bowline. Confirmed defects may be addressed in a scheduled or out-of-cycle maintenance release. Standard support does not include a guaranteed response-time SLA.
License renewal: FID licensed software functionality requires a current license and becomes unavailable after expiration until the license is renewed.
FID is most useful when it is shaped around the system you actually need to exercise. Tell us what sits on the wire, what you need to observe or change, and whether the environment is connected or air-gapped.
Prefer email? Reach us directly at contact@bowlineeng.com.